IP Library Granted Patent US 12,255,889
Granted Patent B2
US 12,255,889 · App. 17/535,261 · Granted Mar 18, 2025

Detecting and preventing unauthorized credential change

Inventor: Asaf Hecht (Petach-Tikva, IL)
Assignee: CyberArk Software Ltd.
H04L63/0846H04L63/102H04L63/1416H04L63/1483H04L63/20G06F21/45G06F2221/2141H04L63/083H04L63/10H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,255,889
App. No.
17/535,261
Granted
Mar 18, 2025
Kind
B2
Abstract

Techniques include securely accessing data associated with at least one identity capable of accessing one or more access-controlled network resources; generating an intermediate value based on the data associated with the at least one identity; generating, based on application of a secret logic algorithm to the intermediate value, a secret data element; making available, the secret data element, to be embedded in an authentication credential associated with the at least one identity; identifying an attempt to change the authentication credential, the attempt including new authentication credential data to replace data in the authentication credential; validating, conditional on a determination whether the new authentication credential data includes the secret data element in a predefined location, the attempt to change the authentication credential; and determining, based on the validating, whether to perform a control action based on the new authentication credential data.

Claims (32)

1. A non-transitory computer readable medium including instructions that, when executed by at least one processor, cause the at least one processor to perform operations for controlling changes to authentication credentials, the operations comprising:

securely accessing data associated with at least one identity capable of accessing one or more access-controlled network resources, wherein the data associated with the at least one identity includes information enabling identification of the at least one identity;

generating an intermediate value based on the data associated with the at least one identity, wherein the intermediate value the information enabling identification of the at least one identity; generating, based on application of a secret logic algorithm to the intermediate value, a secret data element;

making, the secret data element, together with a randomized data portion, available to be embedded in an authentication credential associated with the at least one identity;

identifying an attempt to change the authentication credential by the at least one identity, the attempt including new authentication credential data to replace data in the authentication credential;

validating, conditional on a determination whether the new authentication credential data includes the secret data element in a predefined location, the attempt to change the authentication credential, wherein the secret data element in the predefined location is generated by the at least one identity using the secret logic algorithm and the data associated with the at least one identity; and

determining, based on the validating, whether to perform a control action based on the new authentication credential data.

2. The non-transitory computer readable medium of claim 1 , wherein the data associated with the at least one identity includes at least one of: identity representation information, group relationship information, historical identity data, identity access information, or identity origin information.

3. The non-transitory computer readable medium of claim 2 , wherein the group relationship information includes at least one unique identifier for a group associated with the at least one identity.

4. The non-transitory computer readable medium of claim 2 , wherein the representation of the at least one identity includes an image.

5. The non-transitory computer readable medium of claim 1 , wherein the data associated with the at least one identity includes at least one of: a unique identifier of the at least one identity, a name of the at least one identity, a unique identifier of a group associated with the at least one identity, a creation date, a historical access log, a permission assigned to the at least one identity, a network address associated with the at least one identity, properties of an activity performed by the at least one identity, or an image associated with the at least one identity.

6. The non-transitory computer readable medium of claim 1 , wherein the data associated with the at least one identity includes a combination of two or more categories of data.

7. The non-transitory computer readable medium of claim 1 , wherein generating the secret data element includes performing one or more hashing functions to the data associated with the at least one identity.

8. The non-transitory computer readable medium of claim 7 , wherein performing the one or more hashing functions includes concatenating two or more data elements of the data associated with the at least one identity.

9. The non-transitory computer readable medium of claim 7 , wherein performing the one or more hashing functions includes applying a summation function to the data associated with the at least one identity.

10. The non-transitory computer readable medium of claim 1 , wherein the control action includes rejecting the new authentication credential data.

11. The non-transitory computer readable medium of claim 1 , wherein the control action includes generating an alert identifying the new authentication credential data as a candidate to include a security risk.

12. A computer-implemented method, executed by one or more hardware processors, for controlling changes to authentication credentials, the method comprising:

securely accessing data associated with at least one identity capable of accessing one or more access-controlled network resources, wherein the data associated with the at least one identity includes information enabling identification of the at least one identity;

generating an intermediate value based on the data associated with the at least one identity, wherein the intermediate value includes the information enabling identification of the at least one identity;

generating, based on application of a secret logic algorithm to the intermediate value, a secret data element;

making, the secret data element, together with a randomized data portion, available to be embedded in an authentication credential associated with the at least one identity;

identifying an attempt to change the authentication credential by the at least one identity, the attempt including new authentication credential data to replace data in the authentication credential;

validating, conditional on a determination whether the new authentication credential data includes the secret data element in a predefined location, the attempt to change the authentication credential, wherein the secret data element in the predefined location is generated by the at least one identity using the secret logic algorithm and the data associated with the at least one identity; and

determining, based on the validating, whether to perform a control action based on the new authentication credential data.

13. The computer-implemented method of claim 12 , wherein the method is performed by an agent on the one or more access-controlled network resources.

14. The computer-implemented method of claim 12 , wherein the method is performed by a credential validation resource associated with a secure credentials repository that securely maintains the data associated with the at least one identity.

15. The computer-implemented method of claim 12 , wherein the method is performed by a system configured to intercept a network traffic directed to the one or more access-controlled network resources.

16. The computer-implemented method of claim 12 , wherein the method is performed by a system that securely maintains the data associated with the at least one identity.

17. The computer-implemented method of claim 12 , wherein the method is performed by a system remote from a secure credentials repository that securely maintains the data associated with the at least one identity.

18. The computer-implemented method of claim 12 , wherein the control action includes one or more of: disabling network access for the at least one identity; monitoring activity of the at least one identity; rotating the new authenticating credential data; modifying one or more access permissions for the at least one identity; displaying a request for re-authentication to the at least one identity; or registering the new authentication credential data in a credential repository.

19. The computer-implemented method of claim 12 , wherein the control action is performed on the one or more access-controlled resources, including at least one of: isolating the one or more access-controlled resources from the network, suspending the one or more access-controlled resources, performing forensic analysis, and restoring previous states of the one or more access-controlled resources.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 24, 2021
From: HECHT, ASAF
To: CYBERARK SOFTWARE LTD.
Reel/Frame 058208/0362 →
Continuity (2)
Continuation In Part 15998532 · Aug 16, 2018
Related Publication 20220086142A1 · Mar 17, 2022
References Cited (46)
US 6993658B1 · Engberg et al. · 2006 [cited by applicant]
US 8056123B2 · Correl · 2011 [cited by examiner]
US 8769637B2 · Janzen · 2014 [cited by applicant]
US 8918849B2 · Talamo et al. · 2014 [cited by applicant]
US 8984602B1 · Bailey · 2015 [cited by examiner]
US 8990905B1 · Bailey · 2015 [cited by examiner]
US 9088556B2 · Truskovsky · 2015 [cited by examiner]
US 9264425B1 · Chen · 2016 [cited by examiner]
US 10956560B1 · Sanchez · 2021 [cited by applicant]
US 20060036857A1 · Hwang · 2006 [cited by applicant]
US 20060230437A1 · Boyer et al. · 2006 [cited by applicant]
US 20070006305A1 · Florencio et al. · 2007 [cited by applicant]
US 20070204330A1 · Townsley · 2007 [cited by examiner]
US 20090164489A1 · Matsuda · 2009 [cited by examiner]
US 20090260077A1 · Zhu · 2009 [cited by examiner]
US 20090327740A1 · Schneider · 2009 [cited by examiner]
US 20100218254A1 · Gray, II · 2010 [cited by examiner]
US 20100325690A1 · Suzuki · 2010 [cited by examiner]
US 20110252243A1 · Brouwer · 2011 [cited by examiner]
US 20120297205A1 · Yuen et al. · 2012 [cited by applicant]
US 20140032922A1 · Spilman · 2014 [cited by examiner]
US 20140136057A1 · Dunning · 2014 [cited by examiner]
US 20140181290A1 · Wong · 2014 [cited by examiner]
US 20140325622A1 · Luk et al. · 2014 [cited by applicant]
US 20150058977A1 · Thompson · 2015 [cited by examiner]
US 20150254452A1 · Kohlenberg et al. · 2015 [cited by applicant]
US 20160085962A1 · Sokolov et al. · 2016 [cited by applicant]
US 20160094569A1 · Mondiguing · 2016 [cited by examiner]
US 20170331856A1 · Vissamsetty · 2017 [cited by examiner]
US 20170346797A1 · Yedidi et al. · 2017 [cited by applicant]
US 20180121636A1 · Schiffman et al. · 2018 [cited by applicant]
US 20180144122A1 · Dymond et al. · 2018 [cited by applicant]
US 20180247654A1 · Bhaya · 2018 [cited by examiner]
US 20180337957A1 · Chen · 2018 [cited by examiner]
US 20190007387A1 · Jin et al. · 2019 [cited by applicant]
US 20190007428A1 · Moen · 2019 [cited by examiner]
US 20200052899A1 · Finlow-Bates · 2020 [cited by examiner]
CN 1338167A · 2002 [cited by examiner]
CN 1871810B · 2010 [cited by examiner]
JP 2000187794A · 2000 [cited by examiner]
WO WO2004068351A1 · 2004 [cited by examiner]
WO WO2017033442A1 · 2017 [cited by examiner]
Shammi Ishara Hewamadduma (Detection and Prevention of Possible Unauthorized Login Attempts through Stolen Credentials from a Phishing Attack in an Online Banking System); pp. 6; Published on IEEE (Year: 2017). [cited by examiner]
Alvaro Madero (Password Secured Systems and Negative Authentication); pp. 55; Published on June (Year: 2013). [cited by examiner]
Samuel Gibbs, Passwords And Hacking: The Jargon of Hashing, Salting and SHA-2 Explained, Dec. 15, 2016 (6 pages). [cited by applicant]
Alvaro Madero, Password Secured Systems and Negative Authentication, Jun. 2013 (55 pages). [cited by applicant]